|
WAAP · Web Application & API Protection
One Inline Layer That Protects Every Web App and APIGajWAF is a WAAP (Web Application & API Protection) platform — a web application firewall that inspects every request and response in line — blocking injection, bots, account takeover, API abuse and data leaks — and is run entirely from a browser console. Deploy it on-premises, in the cloud or in a container, in your own environment. Request a Demo See Capabilities |
|
|
Complete WAAP
WAF · API Security · Bots · Layer-7 DoS
|
Deployment
On-Premises · Cloud · Container
|
Compliance Evidence
PCI DSS · HIPAA · GDPR · DPDP · CERT-In · ISO 27001
|
Four Tools, Four Consoles. Gaps In Between.
Most organisations stitch together a web firewall, an API gateway, a bot tool and a reporting pipeline — each bought, integrated and operated on its own. The result is more to run, more to tune, and blind spots where the products don't overlap. That is why industry analysts now treat these as one category: Web Application and API Protection, or WAAP.
|
Gap 1 · Watching, Not Blocking
Many tools are alert-only or inspect sampled traffic. Attacks that aren't sampled — or are only alerted on — still reach the application. |
Gap 2 · Signatures Only
Signature matching misses attacks it has never seen. Zero-days and novel API abuse pass straight through until a rule is written. |
Gap 3 · Data Leaves Your Control
Cloud-hosted WAF services route your traffic and logs outside your environment — and hand auditors raw logs someone has to interpret. |
GajWAF Is a Complete WAAP Platform in One Layer You Own
GajWAF combines web application protection, API security, bot defence, access control and data-leak prevention in a single inline layer — one that you run, tune and own.
Signature, behavioural and machine-learning detection work together with positive security that learns each site's normal traffic, so GajWAF catches the attacks signatures alone would miss.
Inline, Not SampledFull request and response inspection in the traffic path with about 0.2 ms of overhead — it blocks attacks, it doesn't just alert. |
Run It From a BrowserCertificates, rules, schemas, sites, bans and reports are all managed in the console — no command line, no files to hand-edit. |
Deploy AnywhereYour own servers, the cloud or a container. No endpoint agents, no cloud dependency, works fully offline. |
Audit & Compliance ReadyBranded, scheduled reports and evidence mappings for HIPAA, PCI DSS, GDPR, India DPDP/CERT-In and ISO 27001. |
Your Protection at a Glance
The GajWAF dashboard shows what's being blocked, which sites are protected and what needs your attention — all in the browser, with no command line.
Why GajWAF Is Different
How GajWAF as a single WAAP layer compares with the typical stitched-together approach.
| Typical Approach | GajWAF | |
|---|---|---|
| One layer, not many | Separate products for web attacks, APIs, bots and access — each bought, integrated and operated on its own | Web apps, APIs, bots, access control and data-leak prevention in a single layer |
| Enforce, don't just watch | Often alert-only or inspecting sampled traffic, leaving gaps | Inline on every request and response — it blocks, with negligible added latency |
| Anyone can run it | Specialists, command-line tooling and risky manual rule edits | Guided browser console, watch-only mode, one-click undo and one-click fixes for false alarms |
| Catches the unknown | Signature matching only — misses attacks it has never seen | Signatures plus behaviour, machine learning and a model that learns each site's normal traffic |
| Your data stays yours | Cloud service where your traffic and logs leave your control | Runs in your own environment — on-premises, cloud or offline — so data never leaves it |
| Proof, not just logs | Raw logs that someone has to collect and interpret | Board-ready and compliance-mapped reports, generated on demand or scheduled and emailed |
Six WAAP Pillars: Web, API, Bot & Data Protection
Threat detection, API security, bot and abuse defence, data protection, access control and operations — in a single firewall.
|
|
|
|
|
|
Three Ways Attackers Abuse Logins — All Detected
Login and checkout pages are where stolen and guessed credentials get tested. GajWAF recognises each pattern of credential abuse — without ever storing or logging a password.
|
Pattern 1
One client → many accounts
Credential StuffingA single client works through stolen username-and-password pairs, failing across many different accounts as it hunts for the ones that still work. ✓ Detected: one client failing across many accounts
|
Pattern 2
One password → many accounts
Password SprayingOne common password is tried once against many accounts — a slow, quiet approach meant to stay under per-account lockout limits. ✓ Detected: one password tried across many accounts
|
Pattern 3
Many clients → one account
Distributed Account AttackAttempts on a single account are spread across many clients, so no one source looks suspicious on its own. ✓ Detected: one account under attack from many clients
|
What GajWAF Stops
The attack and abuse classes GajWAF detects and blocks across web applications and APIs.
Injection & ExploitationSQL injection, cross-site scripting (XSS), remote code execution, command injection, path traversal / LFI, SSRF, XXE, template injection (SSTI), insecure deserialization, open redirect and remote file inclusion. |
Bots & AbuseAutomated bots & crawlers, content scraping, credential stuffing, password spraying, account takeover, brute force, Layer-7 request floods, vulnerability scanners and carding / fraud probes. |
API, Data & IntegrityAPI schema / contract violations, unauthorized API access, GraphQL abuse, sensitive-data exposure, malware uploads, web defacement, client-side script injection (Magecart), and known-CVE & end-of-life software. |
Where Teams Put GajWAF to Work
From legacy apps that can't be patched to APIs, logins and compliance audits.
Protect Apps You Can't PatchShield legacy, third-party or unpatched applications from known and zero-day exploits with virtual patching — without touching the code. |
Secure Your APIsEnforce each API's contract, verify tokens and keys, and stop abuse, scraping and malformed requests before they reach the service. |
Stop Account TakeoverDefeat credential stuffing, password spraying and bots on login and checkout, and flag suspicious sign-ins — without storing passwords. |
Meet ComplianceSatisfy the web-application control in PCI DSS, HIPAA, GDPR and India's DPDP, and hand auditors mapped evidence reports on demand. |
Add Single Sign-OnPut a modern login in front of internal or legacy applications using your existing directory — no change to the application. |
Ride Out an AttackTurn on emergency mode in one click during a flood or targeted campaign — every visitor passes a quick check until the storm passes. |
Deploy the Way You Run
GajWAF sits inline in front of your applications and runs wherever they do — a self-hosted WAAP with one layer, no agents and no cloud dependency.
On-PremisesOn a GajShield Firewall Appliance, your own server or a virtual machine — in front of your servers, fully inside your network. |
Public or Private CloudRun the same software on Microsoft Azure, AWS or any other cloud or region — no vendor lock-in. |
ContainerRun it alongside your containerised applications and services. |
High-Availability PairActive-passive with a floating address and automatic failover for zero-downtime protection. |
Technical Specifications
| Form factor | Inline software appliance. Installs on your own servers, as a container, or through the included installer. |
| Platforms | GajShield Firewall Appliances, virtual machines, and public cloud on Microsoft Azure and AWS. No endpoint agents and no separate database to run. |
| Deployment | On-premises, private or public cloud, or container. Air-gap and offline updates supported. |
| Performance | About 0.2 ms added inspection latency per request; configuration changes apply live with no downtime. |
| Protocols | HTTP/1.1, HTTP/2 and HTTPS; TLS 1.2–1.3; WebSocket pass-through. Multiple sites / virtual hosts per instance. |
| TLS & certificates | Per-site certificates (upload in the console or automatic issuance & renewal), HSTS, HTTP→HTTPS redirect, private-CA trust for backends. |
| High availability | Active-passive clustering with floating virtual IPs and encrypted state sync (configuration, bans, users). |
| Protection modes | Per site: block, watch-only or off; relaxed / balanced / strict security presets. |
| Management | HTTPS web console (light/dark), API for automation, role-based access and two-factor authentication. |
| Integrations | LDAP / Active Directory, RADIUS and OpenID Connect sign-in; antivirus for upload scanning; location (GeoIP) data; email & webhook alerting; import of existing IPS rulesets. |
| Logging | Built-in searchable event store with configurable retention, CSV export, and an audit log for SIEM forwarding. |
Compliance & Reporting
Generate audience-specific and compliance-mapped reports that document GajWAF's active controls as evidence toward each framework — with a Met / Partial / Gap assessment against each requirement.
Put One Layer in Front of Every App and API
Talk to a GajShield expert about protecting your web applications and APIs with GajWAF, GajShield's WAAP platform — on-premises, in the cloud or in a container.
Request a Demo See Capabilities See the Full Firewall